Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add nibzard/skillsnpx agentmods add plugins/nibzard/skills/skill-creatorgit clone --depth 1 https://github.com/nibzard/skillsGrade A, and why
skill-creator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "skill-creator",
"version": "1.0.0",
"description": "Create new Agent Skills interactively or from templates. Use when building custom skills, scaffolding new capabilities, or when user mentions creating skills, writing skills, skill templates, or skill development.",
"homepage": "https://nibzard.com/skills/skill-creator",
"license": "MIT",
"author": {
"name": "nibzard",
"email": "[email protected]"
}
}What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 11 lines scan A ea3e638f2566
skill-creator is a plugin published in the GitHub repository nibzard/skills (2 stars, last pushed 22d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
developer-kit-java
Comprehensive Java development toolkit with Spring Boot, testing, LangChain4J, and AWS integration.
svix
Teaches AI agents to send and receive webhooks the way Svix's own engineers would.
craft-your-textbook
把教材或某领域知识,加工成 AI 苏格拉底老师能拿去上课的教学蓝本(pure-blueprint),或一本给人读的流畅教材(human-readable,AI 也能直接教)。两条路线触发时自选,默认推荐给 AI 老师的版本。适用任何学科。有教师用书可直接针对应试。.
finding-unknowns-skills
11 skills for finding your unknowns and rightsizing the context you hand an agent: blindspot pass, brainstorm prototypes, interview me, reference hunt, implementation plan, implementation notes, pitch packager, change quiz, context audit, agent interface design, progressive disclosure.
erpaval
Plugin marketplace listing 1 plugin: erpaval.
skill-engine
Teach Claude your codebase, then keep it taught. On opt-in, clones registered git sources to a local cache (/.cache/skill-engine/) and installs per-skill context files under your project's .claude/skills/. Reads only paths you register.